Show filters
44 Total Results
Displaying 31-40 of 44
Sort by:
Attacker Value
Unknown

CVE-2007-5072

Disclosure Date: September 24, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.php files under themes/, as demonstrated by the user_colors[bg_color] parameter.
0
Attacker Value
Unknown

CVE-2007-4157

Disclosure Date: August 03, 2007 (last updated October 04, 2023)
PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication cookie only requires the password hash, not the cleartext version.
0
Attacker Value
Unknown

CVE-2007-3198

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown

CVE-2006-3514

Disclosure Date: July 11, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions, allow remote attackers to execute arbitrary web script or HTML via the (1) name, (2) title, (3) news, (4) description, and (5) sitename parameters.
0
Attacker Value
Unknown

CVE-2006-1243

Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
0
Attacker Value
Unknown

CVE-2006-0372

Disclosure Date: January 22, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.
0
Attacker Value
Unknown

CVE-2006-0318

Disclosure Date: January 19, 2006 (last updated February 22, 2025)
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.
0
Attacker Value
Unknown

CVE-2005-3473

Disclosure Date: November 03, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.
0
Attacker Value
Unknown

CVE-2005-2787

Disclosure Date: September 02, 2005 (last updated February 22, 2025)
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
0
Attacker Value
Unknown

CVE-2005-2733

Disclosure Date: August 30, 2005 (last updated February 22, 2025)
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
0